SSO integrations

Rotate SAML certificates in Microsoft Entra ID

Use these instructions to rotate the certificates used by Masterplan SAML SSO in Microsoft Entra ID. Depending on your configuration, rotate the signing certificate, the encryption certificate, or both.

Before you begin

Rotate the signing certificate

The signing certificate allows Microsoft Entra ID to verify SAML requests signed by Masterplan.

  1. In the Masterplan enterprise application, open Single sign-on.
  2. Under SAML Certificates, select Edit next to Verification certificates (optional).
  3. Select Upload certificate and upload masterplan.com-saml-signing.cer.
  4. Confirm that both the deprecated and current certificates are listed. Verify that their Entra/SHA-1 thumbprints are 140406E19A3C0401BAE5E738272FBA749C78FDC8 for the current certificate and 135515583381ACD2B495B02AF47D8770B28AFC5A for the deprecated certificate. Keep the deprecated certificate configured until it expires.

Microsoft Entra verification certificate configuration with numbered steps

Rotate the encryption certificate

The encryption certificate allows Microsoft Entra ID to encrypt SAML assertions that only Masterplan can decrypt.

  1. In the Masterplan enterprise application, open Token encryption under Security.
  2. Select Import Certificate and upload masterplan.com-saml-encryption.cer.
  3. Open the actions menu for the current certificate, select Activate, and confirm that its status changes to Active.
  4. Confirm that the deprecated certificate remains listed with the status Inactive. Keep it configured until it expires.

Microsoft Entra token encryption configuration with numbered steps

PAGE CONTENT